CVE Vulnerabilities

CVE-2009-0537

Published: Mar 09, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.

Affected Software

NameVendorStart VersionEnd Version
InterixMicrosoft6.0 (including)6.0 (including)
OpenbsdOpenbsd*4.4 (including)
OpenbsdOpenbsd2.0 (including)2.0 (including)
OpenbsdOpenbsd2.1 (including)2.1 (including)
OpenbsdOpenbsd2.2 (including)2.2 (including)
OpenbsdOpenbsd2.3 (including)2.3 (including)
OpenbsdOpenbsd2.4 (including)2.4 (including)
OpenbsdOpenbsd2.5 (including)2.5 (including)
OpenbsdOpenbsd2.6 (including)2.6 (including)
OpenbsdOpenbsd2.7 (including)2.7 (including)
OpenbsdOpenbsd2.8 (including)2.8 (including)
OpenbsdOpenbsd2.9 (including)2.9 (including)
OpenbsdOpenbsd3.0 (including)3.0 (including)
OpenbsdOpenbsd3.1 (including)3.1 (including)
OpenbsdOpenbsd3.2 (including)3.2 (including)
OpenbsdOpenbsd3.3 (including)3.3 (including)
OpenbsdOpenbsd3.4 (including)3.4 (including)
OpenbsdOpenbsd3.5 (including)3.5 (including)
OpenbsdOpenbsd3.6 (including)3.6 (including)
OpenbsdOpenbsd3.7 (including)3.7 (including)
OpenbsdOpenbsd3.8 (including)3.8 (including)
OpenbsdOpenbsd3.9 (including)3.9 (including)
OpenbsdOpenbsd4.0 (including)4.0 (including)
OpenbsdOpenbsd4.1 (including)4.1 (including)
OpenbsdOpenbsd4.2 (including)4.2 (including)
OpenbsdOpenbsd4.3 (including)4.3 (including)

References